2025 CVE Vulnerabilities
45,194 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66020 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Valibot helps validate data using a schema. In versions from 0.31.0 to 1.1.0, the EMOJI_REGEX used in the emoji action i... |
| CVE-2025-12848 | MEDIUM | 6.1 | 0.3% | Nov 26, 2025 | Webform Multiple File Upload module for Drupal 7.x contains a cross-site scripting (XSS) vulnerability in the file name ... |
| CVE-2025-66265 | MEDIUM | 6.9 | 0.1% | Nov 26, 2025 | CMService.exe creates the C:\\usr directory and subdirectories with insecure permissions, granting write access to all a... |
| CVE-2025-66264 | HIGH | 7.2 | 0.1% | Nov 26, 2025 | The CMService.exe service runs with SYSTEM privileges and contains an unquoted service path. This allows a local attacke... |
| CVE-2025-66263 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Unauthenticated Arbitrary File Read via Null Byte Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi... |
| CVE-2025-66262 | CRITICAL | 9.8 | 1.2% | Nov 26, 2025 | Arbitrary File Overwrite via Tar Extraction Path Traversal in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmit... |
| CVE-2025-66261 | CRITICAL | 9.8 | 2.1% | Nov 26, 2025 | Unauthenticated OS Command Injection (restore_settings.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi... |
| CVE-2025-66260 | MEDIUM | 6.5 | 0.3% | Nov 26, 2025 | PostgreSQL SQL Injection (status_sql.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, ... |
| CVE-2025-66259 | CRITICAL | 9.8 | 0.6% | Nov 26, 2025 | Authenticated Root Remote Code Execution via improrer user input filtering in DB Electronica Telecomunicazioni S.p.A. Mo... |
| CVE-2025-66258 | MEDIUM | 5.4 | 0.2% | Nov 26, 2025 | Stored Cross-Site Scripting via XML Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions ... |
| CVE-2025-66257 | CRITICAL | 9.1 | 0.3% | Nov 26, 2025 | Unauthenticated Arbitrary File Deletion (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transm... |
| CVE-2025-66256 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | Unauthenticated Arbitrary File Upload (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmit... |
| CVE-2025-66255 | CRITICAL | 9.8 | 0.3% | Nov 26, 2025 | Unauthenticated Arbitrary File Upload (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transm... |
| CVE-2025-66254 | CRITICAL | 9.1 | 0.3% | Nov 26, 2025 | Unauthenticated Arbitrary File Deletion (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Tran... |
| CVE-2025-66253 | CRITICAL | 9.8 | 2.1% | Nov 26, 2025 | Unauthenticated OS Command Injection (start_upgrade.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitte... |
| CVE-2025-66252 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Infinite Loop Denial of Service via Failed File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitte... |
| CVE-2025-66251 | CRITICAL | 9.1 | 0.4% | Nov 26, 2025 | Unauthenticated Path Traversal with Arbitrary File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi... |
| CVE-2025-66250 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | Unauthenticated Arbitrary File Upload (status_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi... |
| CVE-2025-64657 | CRITICAL | 9.8 | 0.5% | Nov 26, 2025 | Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a ne... |
| CVE-2025-64656 | CRITICAL | 9.8 | 0.5% | Nov 26, 2025 | Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2025-66019 | MEDIUM | 6.6 | 0.3% | Nov 26, 2025 | pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability... |
| CVE-2025-65963 | MEDIUM | 5.4 | 0.2% | Nov 26, 2025 | Files is a module for managing files inside spaces and user profiles. Prior to versions 0.16.11 and 0.17.2, insufficient... |
| CVE-2025-65957 | HIGH | 8.8 | 0.2% | Nov 26, 2025 | Core Bot Is an Open Source discord bot made for maple hospital servers. Prior to commit dffe050, the API keys (SUPABASE_... |
| CVE-2025-65956 | MEDIUM | 5.4 | 0.2% | Nov 26, 2025 | Formwork is a flat file-based Content Management System (CMS). Prior to version 2.2.0, inserting unsanitized data into t... |
| CVE-2025-65953 | MEDIUM | 6 | 0.2% | Nov 25, 2025 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.22.5, a Heap-Use-After-Free (UA... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now